10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants full access to the underlying process. Because the probe runs with host networking and holds all cluster credentials (ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, CLICKHOUSE_PASSWORD) in its environment variables, and monitor creation is available to the lowest role (ProjectMember) with open registration enabled by default, any anonymous user can achieve full cluster compromise in about 30 seconds. This issue has been fixed in version 10.0.5.
AI Analysis
Sandbox escape in custom JavaScript monitor feature allows anonymous users to achieve full cluster compromise
Basic Information
ID
CVE-2026-27574
Source
GitHub_M
Published
Feb 21, 2026 at 10:13
Affected Product
Vendor
OneUptime
Product
oneuptime
Version
< 10.0.5
Affected Versions
OneUptime oneuptime < 10.0.5
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
OneUptime
Product
OneUptime
Version
9.5.13 and below